VMware has released security updates to fix a critical remote code execution vulnerability known as Spring4Shell that affects several of the company's cloud computing and virtualization products.
In the security advisory published by the company, it lists the list of VMware products affected by the Spring4Shell vulnerability. Where a fix is not available, VMware has provided some protection advice as a temporary solution.
See also: Amazon: Phishing email threatens to permanently block accounts

Serious vulnerability in Spring Framework
The Spring4Shell vulnerability, officially known as CVE-2022-22965 , is a remote code execution vulnerability found in the Spring Core Java framework . It can execute code without authentication and has been rated 9.8/10 on the vulnerability severity scale.
According to experts, any malicious user with access to vulnerable applications can execute commands and take full control of a target system.
The Spring Framework is very popular for developing Java applications, so security analysts fear that many criminals are exploiting the Spring4Shell vulnerability. In addition, a proof-of-concept (PoC) exploit has been leaked on GitHub ahead of the security update's release.
See also: Android malware: New spyware has access to a lot of data
The vulnerability affects Spring MVC and Spring WebFlux apps running on JDK 9+. The exploit requires the application to be running on Tomcat as a WAR deployment, although the exact restrictions are still under investigation.
The fixed versions of the applications are:
- Spring Framework 5.3.18 and Spring Framework 5.2.20
- Spring Boot 2.5.12
- Spring Boot 2.6.6 (coming soon)
VMWare has reviewed its products and, while the investigation is still ongoing, has reported that the following products are affected by the Spring4Shell vulnerability:
- VMware Tanzu Application Service for VMs – versions 2.10 to 2.13
- VMware Tanzu Operations Manager – versions 2.8 to 2.9
- VMware Tanzu Kubernetes Grid Integrated Edition (TKGI) – versions 1.11 to 1.13

The company has security updates ready for the first two products, but a permanent fix for VMware Tanzu Kubernetes Grid Integrated Edition is not yet available.
For these deployments, VMWare has published some guidance to help administrators temporarily secure their systems until official updates are released.
See also: Borat malware: New RAT allows DDoS and ransomware attacks
According to VMWare, the Spring4Shell exploit is complex in TKGI, but an update will be released soon.
VMware
VMware, Inc. is an American technology company, headquartered in California, focused on cloud computing and virtualization.
Source: Bleeping Computer
